Malicious RTF — malware analysis report

Static analysis result for SHA-256 a9511050343f897d…

MALICIOUS

RTF

21.0 KB First seen: 2018-01-08
MD5: f2b48bb07311c53646ed1eb804f469a4 SHA-1: ab01fc9e8635d91413e03555aaae04ffcc421055 SHA-256: a9511050343f897dfa32626d952be22c40c5cd67a9dcf17314ad202e31f45958
200 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF document contains OLE object data and triggers an objupdate, indicating an attempt to exploit embedded objects. Critical heuristics identify the use of SOAP Moniker and CVE-2017-8759, a known vulnerability for remote code execution. This suggests the file is designed to exploit this vulnerability to download and execute a secondary payload.

Heuristics 5

  • SOAP Moniker — CVE-2017-8759 (SOAP WSDL RCE) critical CVE related CVE_2017_8759
    RTF \objdata decodes to OLE data containing the SOAP Moniker — CVE-2017-8759 (SOAP WSDL RCE) CLSID — the vulnerable control/moniker is embedded directly in the document's object stream, the delivery shape of this exploit. RTF objects auto-render when Word opens the file.
  • ClamAV: Rtf.Downloader.CVE_2017-6336326-3 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Downloader.CVE_2017-6336326-3
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000054b.bin rtf-objdata-decoded RTF \objdata at offset 0x54B 3194 bytes
SHA-256: 299fab9e08956d158d05113f43840b0159fe10be4d12a1373d1e34ec16081208